ModStealer malware targets crypto wallets on Windows, macOS, and Linux, stealing keys and data. Read how it spreads and how to stay safe.   ModStealer malware is becoming one of the most pressing threats to crypto wallets.  Security researchers discovered that it can now infiltrate systems running Windows, macOS and Linux. Once installed, it extracts […] The post Crypto Researchers Find Another Undetectable Cross-Platform Wallet Drainer appeared first on Live Bitcoin News.ModStealer malware targets crypto wallets on Windows, macOS, and Linux, stealing keys and data. Read how it spreads and how to stay safe.   ModStealer malware is becoming one of the most pressing threats to crypto wallets.  Security researchers discovered that it can now infiltrate systems running Windows, macOS and Linux. Once installed, it extracts […] The post Crypto Researchers Find Another Undetectable Cross-Platform Wallet Drainer appeared first on Live Bitcoin News.

Crypto Researchers Find Another Undetectable Cross-Platform Wallet Drainer

2025/09/13 15:30
3 min read

ModStealer malware targets crypto wallets on Windows, macOS, and Linux, stealing keys and data. Read how it spreads and how to stay safe.

 

ModStealer malware is becoming one of the most pressing threats to crypto wallets. 

Security researchers discovered that it can now infiltrate systems running Windows, macOS and Linux. Once installed, it extracts sensitive information including wallet credentials, private keys and certificates.

The malware was uncovered by Apple-focused security firm Mosyle. According to their findings, ModStealer avoided detection by most antivirus engines for nearly a month after being uploaded to VirusTotal. 

How ModStealer Operates

Mosyle revealed that ModStealer is a feature-rich infostealer. It comes loaded with code designed to harvest sensitive data from browser-based wallet extensions. 

Targets include popular extensions on Safari and Chromium-based browsers.

On macOS systems, the malware gains persistence by using Apple’s launchctl tool. 

It registers itself as a background agent and silently monitors activity. On all operating systems, it can capture clipboard data, take screenshots and even execute remote commands.

Researchers traced the malware’s server to Finland, even though the infrastructure appears to be routed through Germany.

Fake Job Ads Fuel Malware Distribution

The malware is spreading through fake job recruitment ads. Cybercriminals disguise themselves as recruiters offering technical assessments or test tasks. 

Developers who download these files unknowingly install ModStealer and give attackers access to sensitive data.

This tactic has become increasingly common in Web3 communities. Hacken’s Stephen Ajayi, a technical lead in blockchain security, warned that fake test assignments are now a standard tool for attackers.

He advised handling assignments only in disposable virtual machines that contain no wallets, SSH keys, or password managers.

Advice From Security Experts

Ajayi stressed that users must separate their work and wallet environments. He recommended using a “dev box” for development and a “wallet box” for storing digital assets. 

This compartmentalisation reduces the chance of wallet compromise.

He also pointed out the importance of wallet hygiene. Hardware wallets, offline storage of seed phrases and careful confirmation of wallet addresses are all great strategies for reducing exposure.

Malware-as-a-Service Adds Scale

Researchers believe ModStealer is part of a growing Malware-as-a-Service (MaaS) market. 

Criminals package malware for resale to affiliates, who can then deploy it without technical expertise. This model allows for quick scaling of attacks.

Mosyle noted that ModStealer reflects a wider trend in Mac malware. Infostealers now dominate threats targeting Apple systems, with Jamf reporting a 28% rise this year.

Wider Threats to Crypto Users

The risks extend beyond ModStealer. A recent case pointed out how phishing remains one of the most damaging attack methods. 

Blockchain analytics firm Lookonchain reported that an investor lost $3.05 million in Tether (USDT) after unknowingly approving a malicious transaction.

The investor only checked the first and last few characters of a wallet address. Attackers exploited that habit to redirect funds.

According to security firm CertiK, crypto users lost more than $2.2 billion to hacks, scams, and breaches in the first half of the year. 

Wallet hacks alone accounted for $1.7 billion across just 34 incidents. Phishing scams added over $410 million across 132 attacks.

 

Market Opportunity
CROSS Logo
CROSS Price(CROSS)
$0,10365
$0,10365$0,10365
-0,76%
USD
CROSS (CROSS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Buyers Defend Most Major 200-Week Price Average: Can It Be Bottom of 2026?

XRP Buyers Defend Most Major 200-Week Price Average: Can It Be Bottom of 2026?

The post XRP Buyers Defend Most Major 200-Week Price Average: Can It Be Bottom of 2026? appeared on BitcoinEthereumNews.com. XRP has returned to its 200-week moving
Share
BitcoinEthereumNews2026/02/08 19:49
Expert Tags Ethereum’s ERC-8004 Mainnet Launch An “iPhone Moment”, Here’s What It Means

Expert Tags Ethereum’s ERC-8004 Mainnet Launch An “iPhone Moment”, Here’s What It Means

Market analyst says Ethereum is having an “iPhone moment” as it approaches the ERC-8004 mainnet launch.
Share
Coinstats2026/02/08 19:56
Breaking: CME Group Unveils Solana and XRP Options

Breaking: CME Group Unveils Solana and XRP Options

CME Group launches Solana and XRP options, expanding crypto offerings. SEC delays Solana and XRP ETF approvals, market awaits clarity. Strong institutional demand drives CME’s launch of crypto options contracts. In a bold move to broaden its cryptocurrency offerings, CME Group has officially launched options on Solana (SOL) and XRP futures. Available since October 13, 2025, these options will allow traders to hedge and manage exposure to two of the most widely traded digital assets in the market. The new contracts come in both full-size and micro-size formats, with expiration options available daily, monthly, and quarterly, providing flexibility for a diverse range of market participants. This expansion aligns with the rising demand for innovative products in the crypto space. Giovanni Vicioso, CME Group’s Global Head of Cryptocurrency Products, noted that the new options offer increased flexibility for traders, from institutions to active individual investors. The growing liquidity in Solana and XRP futures has made the introduction of these options a timely move to meet the needs of an expanding market. Also Read: Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple! Rapid Growth in Solana and XRP Futures Trading CME Group’s decision to roll out options on Solana and XRP futures follows the substantial growth in these futures products. Since the launch of Solana futures in March 2025, more than 540,000 contracts, totaling $22.3 billion in notional value, have been traded. In August 2025, Solana futures set new records, with an average daily volume (ADV) of 9,000 contracts valued at $437.4 million. The average daily open interest (ADOI) hit 12,500 contracts, worth $895 million. Similarly, XRP futures, which launched in May 2025, have seen significant adoption, with over 370,000 contracts traded, totaling $16.2 billion. XRP futures also set records in August 2025, with an ADV of 6,600 contracts valued at $385 million and a record ADOI of 9,300 contracts, worth $942 million. Institutional Demand for Advanced Hedging Tools CME Group’s expansion into options is a direct response to growing institutional interest in sophisticated cryptocurrency products. Roman Makarov from Cumberland Options Trading at DRW highlighted the market demand for more varied crypto products, enabling more advanced risk management strategies. Joshua Lim from FalconX also noted that the new options products meet the increasing need for institutional hedging tools for assets like Solana and XRP, further cementing their role in the digital asset space. The launch of options on Solana and XRP futures marks another step toward the maturation of the cryptocurrency market, providing a broader range of tools for managing digital asset exposure. SEC’s Delay on Solana and XRP ETF Approvals While CME Group expands its offerings, the broader market is also watching the progress of Solana and XRP exchange-traded funds (ETFs). The U.S. Securities and Exchange Commission (SEC) has delayed its decisions on multiple crypto-related ETF filings, including those for Solana and XRP. Despite the delay, analysts anticipate approval may be on the horizon. This week, REX Shares and Osprey Funds are expected to launch an XRP ETF that will hold XRP directly and allocate at least 40% of its assets to other XRP-related ETFs. Despite the delays, some analysts believe that approval could come soon, fueling further interest in these assets. The delay by the SEC has left many crypto investors awaiting clarity, but approval of these ETFs could fuel further momentum in the Solana and XRP futures markets. Also Read: Tether CEO Breaks Silence on $117,000 Bitcoin Price – Market Reacts! The post Breaking: CME Group Unveils Solana and XRP Options appeared first on 36Crypto.
Share
Coinstats2025/09/18 02:35